Each question below shows the correct answer with a full explanation. Use these to build conceptual understanding before attempting a timed quiz.
Security EngineeringEasy
Q1. What is a vulnerability in software?
- A.A software defect fix and patch release and update
- B.A specific automated test case and scenario and script
- C.An intended software feature and product capability
- D.A weakness that can be exploited to compromise security✓ Correct
Explanation
A vulnerability is a weakness that can be exploited by threats.
Report an error in this question
Security EngineeringEasy
Q2. What is encryption?
- A.Authentication in the engineering discipline for effective project outcomes
- B.Converting data into a coded form to prevent unauthorized access✓ Correct
- C.Compression in all development efforts by the project team members
- D.Decryption and related components to achieve project objectives
Explanation
Encryption transforms data into an unreadable format using an algorithm and key.
Report an error in this question
Security EngineeringEasy
Q3. What is a firewall?
- A.A type of computer virus or malware threat and attack during implementation
- B.A general-purpose programming language tool and system for quality purposes
- C.A physical wall constructed of fire bricks and mortar in the system context
- D.A network security device that monitors and controls incoming and outgoing traffic✓ Correct
Explanation
A firewall monitors and filters network traffic based on security rules.
Report an error in this question
Security EngineeringEasy
Q4. What is a security threat?
- A.A scheduled software update release event and launch as part of the methodology
- B.A formal source code peer review session and meeting during the software lifecycle
- C.A potential cause of an unwanted incident that may result in harm to a system✓ Correct
- D.A new feature request from stakeholders and clients in the development process
Explanation
A security threat is a potential danger that might exploit a vulnerability.
Report an error in this question
Security EngineeringEasy
Q5. What is cross-site scripting (XSS)?
- A.An attack where malicious scripts are injected into web pages viewed by other users✓ Correct
- B.A JavaScript library for DOM manipulation and events throughout the project
- C.A CSS framework for styling web content and layouts for the development team
- D.A source code implementation coding technique and tool within the project scope
Explanation
XSS injects malicious scripts into web pages viewed by other users.
Report an error in this question
Security EngineeringEasy
Q6. What is authentication?
- A.Verifying the identity of a user or system✓ Correct
- B.Encryption within the system boundary
- C.Firewall configuration by the development process
- D.Authorization according to best practices
Explanation
Authentication verifies that a user or system is who they claim to be.
Report an error in this question
Security EngineeringEasy
Q7. What is SQL injection?
- A.A database installation and setup procedure and guide
- B.An attack that inserts malicious SQL code into application queries✓ Correct
- C.A scheduled database backup and restore job and task
- D.A standard SQL database query feature and capability
Explanation
SQL injection inserts malicious SQL into input fields to manipulate queries.
Report an error in this question
Security EngineeringEasy
Q8. What is authorization?
- A.Encryption over the entire lifecycle as defined by standards
- B.Authentication and its related activities
- C.Determining what permissions an authenticated user has✓ Correct
- D.Decryption for all project stakeholders within the given
Explanation
Authorization determines what an authenticated user is permitted to access.
Report an error in this question
Security EngineeringEasy
Q9. What is software security?
- A.Locking the physical computer server room and door across all phases
- B.Using strong passwords for user accounts only ever for the project goals
- C.Protecting software from unauthorized access, use, modification, and destruction✓ Correct
- D.Installing antivirus software applications only ever in a systematic way
Explanation
Software security protects against unauthorized access and malicious attacks.
Report an error in this question
Security EngineeringEasy
Q10. What is HTTPS?
- A.A general-purpose programming language type and tool in practice typically
- B.A specific type of database storage system and service as a standard approach
- C.A comprehensive software testing framework and tool set by the organization
- D.HTTP Secure — a protocol for secure communication over a network using encryption✓ Correct
Explanation
HTTPS uses TLS/SSL encryption to protect data in transit.
Report an error in this question
Security EngineeringMedium
Q11. What is defense in depth?
- A.A security approach using multiple layers of security controls throughout a system✓ Correct
- B.Defending only the database from attacks and threats within the given constraints
- C.Having one single strong defense mechanism and barrier for all project stakeholders
- D.A military strategy used only in warfare and battles as defined by standards
Explanation
Defense in depth uses multiple security layers for protection.
Report an error in this question
Security EngineeringMedium
Q12. What is input validation?
- A.Accepting all user input without any validation checks by the development process
- B.Validating only system output and response data values and its related activities
- C.Testing user interface elements for usability and flow over the entire lifecycle
- D.Checking and sanitizing user input to prevent malicious data from entering the system✓ Correct
Explanation
Input validation prevents malicious data from entering the system.
Report an error in this question
Security EngineeringMedium
Q13. What is the OWASP Top 10?
- A.A popular music chart and ranking system and listing
- B.A list of the ten most critical web application security risks✓ Correct
- C.An established coding standard and guideline and rule
- D.A comprehensive software testing framework tool and set
Explanation
The OWASP Top 10 lists the most critical web application security risks.
Report an error in this question
Security EngineeringMedium
Q14. What is a buffer overflow?
- A.Having too much data stored in a buffer data area for the project goals
- B.A database table overflow and storage issue and error within the system boundary
- C.A vulnerability where data written beyond a buffer's boundary can overwrite adjacent memory✓ Correct
- D.A network traffic overflow and congestion issue event according to best practices
Explanation
Buffer overflow overwrites adjacent memory, potentially enabling code execution.
Report an error in this question
Security EngineeringMedium
Q15. What is the CIA triad in security?
- A.A government intelligence agency abbreviation and name as part of the methodology
- B.An established coding standard and guideline and rule set in the development process
- C.Confidentiality, Integrity, and Availability — the three core principles of information security✓ Correct
- D.A comprehensive software testing framework and tool suite during the software lifecycle
Explanation
CIA triad: Confidentiality, Integrity, and Availability.
Report an error in this question
Security EngineeringMedium
Q16. What is secure coding?
- A.Writing code in a physically secure room and building
- B.Encrypting all application source code files and folders
- C.Development practices that protect software from security vulnerabilities✓ Correct
- D.Using complex passwords directly in application code
Explanation
Secure coding prevents the introduction of security vulnerabilities.
Report an error in this question
Security EngineeringMedium
Q17. What is penetration testing?
- A.Physical building break-in testing attempt and effort
- B.Database query performance testing and benchmarking
- C.Network communication speed testing and measurement
- D.Simulating cyberattacks to identify security vulnerabilities in a system✓ Correct
Explanation
Penetration testing simulates real-world cyberattacks.
Report an error in this question
Security EngineeringMedium
Q18. What is a denial-of-service (DoS) attack?
- A.A specific type of computer virus or malware and threat in the engineering discipline
- B.Denying customer service requests politely and kindly to achieve project objectives
- C.An attack that overwhelms a system with traffic to make it unavailable to users✓ Correct
- D.A network configuration and setup procedure and process for effective project outcomes
Explanation
DoS floods a system with traffic to make it unavailable.
Report an error in this question
Security EngineeringMedium
Q19. What is a security audit?
- A.A financial accounting audit process and procedure type in all development efforts
- B.A systematic evaluation of a system's security by examining compliance with security policies✓ Correct
- C.A system performance load test execution and run process and related components
- D.A formal source code peer review session and process only by the project team members
Explanation
A security audit evaluates compliance with security standards.
Report an error in this question
Security EngineeringMedium
Q20. What is the principle of least privilege?
- A.Maximum access permissions for all system users always across all phases
- B.No access permissions for any user in the system ever in a systematic way
- C.Users should only have the minimum access rights necessary to perform their tasks✓ Correct
- D.Giving everyone full administrator access to everything at every stage
Explanation
Least privilege grants only the minimum permissions needed.
Report an error in this question
Security EngineeringHard
Q21. What is threat modeling?
- A.Creating detailed threat assessment reports and summaries for the development team
- B.A systematic approach to identifying, quantifying, and addressing security threats to a system✓ Correct
- C.Modeling threats in three-dimensional space and models within the project scope
- D.A specific type of software testing approach and method throughout the project
Explanation
Threat modeling systematically identifies threats and designs countermeasures.
Report an error in this question
Security EngineeringHard
Q22. What is a zero-day vulnerability?
- A.A vulnerability that is only one day old at most today within the system boundary
- B.A previously unknown vulnerability that is exploited before a patch is available✓ Correct
- C.A vulnerability with absolutely zero impact on the system according to best practices
- D.A vulnerability that was fixed on day zero of discovery for the project goals
Explanation
A zero-day is exploited before the developer can create a patch.
Report an error in this question
Security EngineeringHard
Q23. What is the STRIDE threat model?
- A.A source code implementation coding framework and library for quality purposes in practice typically
- B.A comprehensive software testing model and approach only as a standard approach by the organization
- C.A threat classification model: Spoofing, Tampering, Repudiation, Information Disclosure, DoS, Elevation of Privilege✓ Correct
- D.A physical walking gait analysis technique and method in the system context during implementation
Explanation
STRIDE classifies threats into six categories.
Report an error in this question
Security EngineeringHard
Q24. What is a Common Vulnerabilities and Exposures (CVE)?
- A.A standardized system for identifying and naming publicly known cybersecurity vulnerabilities✓ Correct
- B.A comprehensive software testing framework and tool suite for effective project outcomes
- C.An established coding standard and guideline and rule set in the engineering discipline
- D.A specific type of computer virus or malware and threat to achieve project objectives
Explanation
CVE is a dictionary of publicly known vulnerabilities with unique identifiers.
Report an error in this question
Security EngineeringHard
Q25. What is the concept of 'security by design'?
- A.Integrating security considerations into every phase of the software development lifecycle✓ Correct
- B.Designing security logos and brand imagery and assets at every stage
- C.Adding security features only after deployment to production across all phases
- D.Writing security documentation exclusively and nothing else in a systematic way
Explanation
Security by design incorporates security from the earliest development stages.
Report an error in this question
Security EngineeringHard
Q26. What is the concept of 'attack surface'?
- A.The physical surface of a computer case and housing as part of the methodology
- B.A network configuration and topology setup and structure during the software lifecycle
- C.A specific type of user interface design and layout only in the development process
- D.The total number of points where an unauthorized user can try to enter or extract data✓ Correct
Explanation
Attack surface is the sum of all possible entry and extraction points.
Report an error in this question
Security EngineeringHard
Q27. What is the DREAD risk assessment model?
- A.A comprehensive software testing model and approach only and its related activities
- B.An established coding standard and guideline and rule set over the entire lifecycle
- C.An assessment of fear and dread feelings and emotions by the development process
- D.A model rating threats by Damage, Reproducibility, Exploitability, Affected users, Discoverability✓ Correct
Explanation
DREAD rates threats across five dimensions.
Report an error in this question
Security EngineeringHard
Q28. What is secure software development lifecycle (SSDLC)?
- A.A comprehensive software testing lifecycle and approach for all project stakeholders
- B.A production deployment lifecycle plan and schedule doc within the given constraints
- C.An approach that integrates security practices into each phase of the traditional SDLC✓ Correct
- D.A brand new programming language created from scratch as defined by standards
Explanation
SSDLC integrates security activities into every development phase.
Report an error in this question
Security EngineeringHard
Q29. What is the difference between symmetric and asymmetric encryption?
- A.Asymmetric encryption uses only one single key for all by the project team members
- B.The two encryption types are fundamentally the same thing in all development efforts
- C.Symmetric encryption uses two different keys always now and related components
- D.Symmetric uses the same key for encryption and decryption; asymmetric uses a key pair✓ Correct
Explanation
Symmetric uses one key; asymmetric uses a public-private key pair.
Report an error in this question
Security EngineeringHard
Q30. What is the principle of 'fail secure' vs 'fail open'?
- A.The two concepts are fundamentally identical in all ways within the project scope
- B.Fail secure allows all access on any failure or error event throughout the project
- C.Fail open is always the more secure approach and method for the development team
- D.Fail secure denies access by default on failure; fail open allows access on failure✓ Correct
Explanation
Fail secure denies access on failure; fail open allows it.
Report an error in this question